<div dir="ltr">On Tue, Jul 30, 2013 at 7:47 PM, David Bantz <span dir="ltr">&lt;<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>&gt;</span> wrote:<br><div class="gmail_extra"><div class="gmail_quote">

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word"><div style="font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;word-spacing:0px">

<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal">The config below for a single server configured to trust a single imported server cert works (with needed assist from Daniel Fisher).</div>

<div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal">There seem to be at least two conceivable routes to add redundancy:</div><div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal">

<br></div><div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal"><span style="white-space:pre-wrap">        </span>(A) &quot;stacked&quot; login modules for multiple AD server instances:</div>
<div style="text-align:-webkit-auto">
<span style="text-align:left"><span style="white-space:pre-wrap">                </span>edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient</span></div><div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal">

<code style="font-size:1em!important;line-height:1.2em!important;text-align:left;white-space:pre-wrap;border-top-left-radius:0px!important;border-top-right-radius:0px!important;border-bottom-right-radius:0px!important;border-bottom-left-radius:0px!important;background-image:none!important;border:0px!important;float:none!important;min-height:auto!important;margin:0px!important;outline:0px!important;overflow:visible!important;padding:0px!important;vertical-align:baseline!important;width:auto!important;font-family:Consolas,&#39;Bitstream Vera Sans Mono&#39;,&#39;Courier New&#39;,Courier,monospace!important">       ldapUrl=</code><code style="font-size:1em!important;line-height:1.2em!important;text-align:left;white-space:pre-wrap;border-top-left-radius:0px!important;border-top-right-radius:0px!important;border-bottom-right-radius:0px!important;border-bottom-left-radius:0px!important;background-image:none!important;border:0px!important;float:none!important;min-height:auto!important;margin:0px!important;outline:0px!important;overflow:visible!important;padding:0px!important;vertical-align:baseline!important;width:auto!important;font-family:Consolas,&#39;Bitstream Vera Sans Mono&#39;,&#39;Courier New&#39;,Courier,monospace!important;color:rgb(0,51,102)!important">&quot;ldap://</code><a style="font-family:&#39;Andale Mono&#39;">ad02.ua.ad.alaska.edu:3268</a><span style="font-family:&#39;Andale Mono&#39;">&quot;</span></div>

<div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal"><span style="white-space:pre-wrap">                </span>…</div><div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal">

<span style="white-space:pre-wrap">                </span><span style="line-height:14px;text-align:left;font-size:12px;white-space:pre-wrap;font-family:Consolas,&#39;Bitstream Vera Sans Mono&#39;,&#39;Courier New&#39;,Courier,monospace">edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient</span></div>

<div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal"><span style="white-space:pre-wrap">                </span><code style="font-size:1em!important;line-height:1.2em!important;text-align:left;white-space:pre-wrap;border-top-left-radius:0px!important;border-top-right-radius:0px!important;border-bottom-right-radius:0px!important;border-bottom-left-radius:0px!important;background-image:none!important;border:0px!important;float:none!important;min-height:auto!important;margin:0px!important;outline:0px!important;overflow:visible!important;padding:0px!important;vertical-align:baseline!important;width:auto!important;font-family:Consolas,&#39;Bitstream Vera Sans Mono&#39;,&#39;Courier New&#39;,Courier,monospace!important">ldapUrl=</code><code style="font-size:1em!important;line-height:1.2em!important;text-align:left;white-space:pre-wrap;border-top-left-radius:0px!important;border-top-right-radius:0px!important;border-bottom-right-radius:0px!important;border-bottom-left-radius:0px!important;background-image:none!important;border:0px!important;float:none!important;min-height:auto!important;margin:0px!important;outline:0px!important;overflow:visible!important;padding:0px!important;vertical-align:baseline!important;width:auto!important;font-family:Consolas,&#39;Bitstream Vera Sans Mono&#39;,&#39;Courier New&#39;,Courier,monospace!important;color:rgb(0,51,102)!important">&quot;ldap://</code><a style="font-family:&#39;Andale Mono&#39;">ad03.ua.ad.alaska.edu:3268</a><span style="font-family:&#39;Andale Mono&#39;">&quot;</span></div>

<div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal"><span style="white-space:pre-wrap">                </span>..., or</div><div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal">

<br></div><div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal"><span style="white-space:pre-wrap">        </span>(B) &quot;failover&quot; configuration with multiple server instances in a single module:</div>

<div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal"><span style="white-space:pre-wrap">                </span><span style="text-align:left">edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient</span></div>

<div style="font-family:Helvetica;font-size:medium;line-height:normal;white-space:normal"><span style="text-align:left"><span style="white-space:pre-wrap">                </span></span><code style="font-size:1em!important;line-height:1.2em!important;text-align:left;white-space:pre-wrap;border-top-left-radius:0px!important;border-top-right-radius:0px!important;border-bottom-right-radius:0px!important;border-bottom-left-radius:0px!important;background-image:none!important;border:0px!important;float:none!important;min-height:auto!important;margin:0px!important;outline:0px!important;overflow:visible!important;padding:0px!important;vertical-align:baseline!important;width:auto!important;font-family:Consolas,&#39;Bitstream Vera Sans Mono&#39;,&#39;Courier New&#39;,Courier,monospace!important">ldapUrl=</code><code style="font-size:1em!important;line-height:1.2em!important;text-align:left;white-space:pre-wrap;border-top-left-radius:0px!important;border-top-right-radius:0px!important;border-bottom-right-radius:0px!important;border-bottom-left-radius:0px!important;background-image:none!important;border:0px!important;float:none!important;min-height:auto!important;margin:0px!important;outline:0px!important;overflow:visible!important;padding:0px!important;vertical-align:baseline!important;width:auto!important;font-family:Consolas,&#39;Bitstream Vera Sans Mono&#39;,&#39;Courier New&#39;,Courier,monospace!important;color:rgb(0,51,102)!important">&quot;ldap://</code><a style="font-family:&#39;Andale Mono&#39;">fbk-adua02.ua.ad.alaska.edu:3268</a> <code style="font-size:1em!important;line-height:1.2em!important;text-align:left;white-space:pre-wrap;border-top-left-radius:0px!important;border-top-right-radius:0px!important;border-bottom-right-radius:0px!important;border-bottom-left-radius:0px!important;background-image:none!important;border:0px!important;float:none!important;min-height:auto!important;margin:0px!important;outline:0px!important;overflow:visible!important;padding:0px!important;vertical-align:baseline!important;width:auto!important;font-family:Consolas,&#39;Bitstream Vera Sans Mono&#39;,&#39;Courier New&#39;,Courier,monospace!important;color:rgb(0,51,102)!important">ldap://</code><a style="font-family:&#39;Andale Mono&#39;">fbk-adua03.ua.ad.alaska.edu:3268</a><span style="font-family:&#39;Andale Mono&#39;">&quot;</span></div>

<div style="font-size:medium;line-height:normal;white-space:normal"><font face="Andale Mono">       </font><span style="font-family:&#39;Andale Mono&#39;">sslSocketFactory=&quot;{trustCertificates=file:/opt/shibboleth-idp/trustedservercerts/????}&quot;</span></div>

</div></div></div></div></div></blockquote><div><br></div><div>I think your own experience would indicate that (A) is the preferred option. Failover (B) only fails over on *connection* failures. Other types of failure modes that may be important to you won&#39;t cause the next host to be tried. Stacked modules should be tried in order until authentication succeeds.</div>

<div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>